GregLab | Exam Prep

Identify the core features and objects of Microsoft 365 services

Zero Trust and Defender XDR

Core

Use Zero Trust reasoning and understand how protection signals, intelligence, alerts, incidents, and investigation fit together.

Aligned to the current AB-900 guide, verified July 22, 2026.

Why this matters

AB-900 expects administrators to apply Zero Trust reasoning and understand how Defender XDR turns individual security signals into an investigation story.

Must Know

  • Zero Trust uses three principles: verify explicitly, use least privilege, and assume breach.
  • Authentication proves identity; authorization decides what the authenticated identity may do.
  • Threat protection prevents, detects, investigates, responds, and recovers; threat intelligence adds context about actors, campaigns, techniques, and indicators.
  • An alert is one detection signal; an incident correlates related alerts and entities into a broader attack story.
  • Defender XDR combines signals across supported identities, endpoints, email, apps, and cloud activity for investigation and response.
  • Correlation helps prioritize evidence, but administrators still validate scope and choose proportionate remediation.

Compare and Distinguish

  • Authentication vs authorization: prove identity vs decide permitted action.
  • Threat protection vs threat intelligence: operational controls and response vs contextual knowledge used to improve those decisions.
  • Alert vs incident: one detection signal vs a correlated collection that tells a broader attack story.
  • Correlation vs investigation: automated relationship-building vs human/automated analysis that validates cause, scope, and response.
  • Zero Trust assume breach vs giving up on prevention: prepare for compromise and limit impact while still preventing and detecting attacks.

Scenario examples

  • Scenario: A malicious email alert and a suspicious endpoint process involve the same user. Think: Open the Defender XDR incident to view the correlated story and affected entities.
  • Scenario: An IP address is associated with a known campaign. Think: Threat intelligence increases context and urgency, but the administrator still checks tenant evidence before containment.
  • Scenario: A user passes MFA but requests an unusually privileged action. Think: Authentication succeeded; authorization and least privilege still determine whether the action is allowed.
  • Scenario: One low-severity alert is part of a larger incident. Think: Assess it in incident context rather than closing it solely on its individual severity.

Exam traps

  • Threat intelligence does not replace investigation and an alert does not prove malicious intent.
  • Defender XDR incidents do not assign licenses, SharePoint permissions, or Conditional Access rules.
  • MFA is authentication; it does not authorize every resource or remove the need for least privilege.
  • Assume breach does not mean every user is malicious; it means continuously verify and limit impact.

Key takeaways

  • Verify explicitly; use least privilege; assume breach.
  • Protection detects and responds; intelligence adds context; investigation establishes what happened.
  • Alerts correlate into incidents; incidents guide coordinated investigation and response.
How it works
  • Security products create alerts from detections. Defender XDR correlation connects related alerts and entities into an incident, which can be updated or merged as new evidence arrives.
  • Threat intelligence enriches IP addresses, domains, URLs, files, actors, and campaigns and helps analysts decide whether a signal is expected, suspicious, or part of a known technique.
  • Investigation moves from signal to evidence: validate the alert, review correlated activity and affected entities, determine scope and impact, contain or remediate, and document the outcome.
Objects and administrative surfaces
  • Incidents, alerts, evidence, affected assets, advanced hunting, automated investigation, and threat intelligence — Microsoft Defender portal.
  • Conditional Access, identity risk, authentication, and access policy — Microsoft Entra admin center.
  • Workload-specific prevention policies and onboarding supply the signals that Defender XDR correlates.
When to use it
  • Use Defender XDR when related signals across identities, devices, email, or apps need a coordinated investigation.
  • Use threat intelligence to enrich an unfamiliar indicator, understand a campaign, or prioritize exposure—not as the sole basis for declaring an incident resolved.
  • Use Entra or resource permissions for access enforcement; use Defender for threat detection, investigation, and response.
Security and governance implications
  • Give security operators only the roles required for investigation and response, and audit high-impact remediation.
  • Pair prevention with identity, device, data, and monitoring controls so one failure does not become tenant-wide compromise.
  • Treat automated investigation conclusions as evidence to review, especially before disruptive response actions.
Troubleshooting signals
  • Start with incident severity, status, timeline, correlated alerts, affected assets, and evidence; then validate relevant entities and activity in the source workload.
  • If expected signals are absent, confirm the relevant Defender product is licensed, onboarded, healthy, and sending telemetry.
  • Before closing an alert, determine whether it belongs to an incident, whether intelligence changes its meaning, and whether containment or remediation is complete.
More detail
  • Verify explicitly means use all available identity, device, location, service, and risk context instead of trusting a request because it came from an internal network. Least privilege limits access in scope and time. Assume breach limits blast radius, monitors continuously, and prepares to respond.
  • Authentication establishes who or what is requesting access. Authorization evaluates what that authenticated principal may do. Zero Trust uses both: strong authentication does not justify broad authorization.
  • Threat protection is the set of controls and operations that reduce attacks: prevention policies, detections, alerts, investigation, automated or manual remediation, and recovery. Threat intelligence adds knowledge about threat actors, campaigns, techniques, infrastructure, and indicators so defenders can interpret and prioritize evidence.
  • An alert is a signal about suspicious or malicious activity. An incident groups correlated alerts and associated entities—such as users, mailboxes, devices, or files—into a probable attack story. Correlation reduces isolated triage but still requires validation.
  • Microsoft Defender XDR (extended detection and response) unifies signals from supported endpoint, identity, email/collaboration, application, and cloud-app security products. Investigators use the incident timeline, evidence, affected assets, alerts, hunting data, and automated investigation results to understand scope and choose response actions.

Ready for the quiz?

  • Why does successful authentication not guarantee authorization?
  • How is threat intelligence different from threat protection?
  • Why should an alert be reviewed in its incident context?
  • What does “assume breach” change about access and monitoring?

Related objectives

  • D1.2.a — Explain the core Zero Trust principles
  • D1.2.b — Understand authorization
  • D1.2.c — Understand authentication methods
  • D1.2.d — Understand threat protection and intelligence
  • D1.2.e — Understand features and capabilities of Microsoft Defender XDR

Learn more

Free Microsoft 365 Copilot and Agent Administration Fundamentals prep

Build focused AB-900 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not identify the specific item types that will appear on an individual exam before delivery. This lane counts multiple-choice and multiple-response items as exam-style practice. Ordering and matching are supplemental learning exercises and do not count toward exam-style accuracy. Difficulty labels are calibrated to AB-900 Fundamentals, not a Microsoft-published question rating.

Reference

AB-900 topics and reference map

Study links

AB-900 resources